familyphorpiexconfidencehighmalware-familyloadermalware-bazaarattribution
SHA-256: 67ae1ba4090ec9277beb8bdc56379716cc59054d9a5151886cc91838eed217b9

phorpiex: 67ae1ba4 — sextortion spam bot $800 variant, mutex t1, "YOU PERVERT!" window title

Executive Summary

Self-contained MSVC 9.0 PE32 sextortion spam bot, compiled 2026-05-29 12:13:57 UTC. Mutex t1, $800 BTC ransom demand, wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K. Same Tmlr XOR+NOT decrypt key and SMTP engine as the t2/t4/t5 siblings. New delta: window title string YOU PERVERT! I RECORDED YOU! (not observed in prior siblings). Static-only — CAPE skipped (no Windows guest).

What It Is

  • SHA-256: 67ae1ba4090ec9277beb8bdc56379716cc59054d9a5151886cc91838eed217b9
  • File: PE32 executable (GUI) Intel 80386, 5 sections, 18 944 bytes ^[file.txt]
  • Compile time: 2026-05-29 12:13:57 UTC (PE timestamp 0x6A198305) ^[pefile.txt:34]
  • Toolchain: MSVC 9.0 / MSVCR90.dll static CRT, LinkerVersion 9.0 ^[pefile.txt:45] ^[rabin2-info.txt:17]
  • Linker flags: IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE ^[pefile.txt:74]
  • YARA: PE_File_Generic, Suspicious_Wininet_Imports ^[yara.txt]
  • OpenCTI labels: dropped-by-phorpiex, exe, malware-bazaar ^[metadata.json]
  • SSDeep: 192:NIISCngTBvblVPT0Y76fIkq2NleQY9T4KUSvu9zw+ggSmOiMbO5Ot1EdkF39TGJ4:PIblVP4Y/2N0bLu9JgPL7Nyav8U9c8 ^[ssdeep.txt]

How It Works

Entry & Mutex Gating

main() sleeps 2000 ms, creates mutex t1 via CreateMutexA ^[r2:main]. If GetLastError() == ERROR_ALREADY_EXISTS (0xB7), the process exits cleanly — single-instance enforcement. ^[r2:main]

Self-Erasure — Zone.Identifier ADS Deletion

Resolves its own module path via GetModuleFileNameW, formats %s:Zone.Identifier, and deletes the ADS via DeleteFileW. This removes the "Downloaded from Internet" mark that Windows adds to browser-downloaded files. ^[r2:main] ^[strings.txt:19]

External IP Discovery

Calls fcn.00401800 which opens http://icanhazip.com/ via InternetOpenA / InternetOpenUrlA (WinInet), reads the response, and wraps it in [%s] brackets. If the fetch fails, falls back to [0.0.0.0]. ^[r2:fcn.00401800] ^[strings.txt:18]

String Decryption — XOR+NOT (Tmlr key)

All SMTP strings and email template strings are stored encrypted in .rdata. fcn.00401030 decrypts in-place using a 4-byte key Tmlr (0x546d6c72): each plaintext byte = NOT(ciphertext_byte ^ key_byte[key_index % 4]). ^[r2:fcn.00401030]

This is the identical decrypt key used by siblings edd6ad22, 150e4652, c3b1b4e4, dc2936ea, and 5076fdc3. ^[entities/phorpiex.md]

SMTP Engine — Self-Contained Spam Dispatch

fcn.004024e0 (threadproc spawned by main) drives the spam loop:

  1. Seed PRNG with GetTickCount() via srand.
  2. Download victim list from a C2 URL (decrypted at runtime) via fcn.00401900, which uses InternetOpenW with Chrome/202 UA and writes the response to %TEMP%\<n>.txt.
  3. Parse victims from the downloaded text file — splits on :, //, @ to extract email addresses and SMTP server details. ^[r2:fcn.00402340]
  4. Spawn 50 worker threads per outer iteration (outer loop runs 100 iterations = up to 5 000 total threads), each calling fcn.00401a10 to perform a full SMTP dialogue:
    • HELO / EHLO host ^[r2:fcn.00401a10]
    • MAIL FROM: (sender spoofed from victim's own domain) ^[r2:fcn.00401a10]
    • RCPT TO: ^[r2:fcn.00401a10]
    • DATA with full email body ^[r2:fcn.00401a10]
    • QUIT ^[r2:fcn.00401a10]
  5. Email body assembly includes a forged Received: header claiming MailEnable ESMTP, random IP octets, and the full sextortion template (see Interesting Tidbits).
  6. Sleeps 20 s between outer loops, then deletes the temp file and re-fetches.

Thread Count

The outer loop runs 100 iterations, inner loop spawns 50 threads each = 5 000 concurrent SMTP threads, matching the t2/t4/t5 sibling configuration. ^[r2:fcn.004024e0]

Decompiled Behavior

entry0 (0x00402bb7)

Standard MSVC 9.0 CRT startup: GetStartupInfoA, InterlockedCompareExchange spinlock on module init, _initterm_e, _initterm, then calls main. No initterm hijack — honest CRT flow. ^[r2:entry0]

main (0x00402740)

Sleep(2000);
CreateMutexA(NULL, FALSE, "t1");
if (GetLastError() == ERROR_ALREADY_EXISTS) exit;
DeleteFileW("<self>:Zone.Identifier");
WSAStartup(0x0202, &wsaData);
if (DnsQuery_A("yahoo.com", ...) == 0) {
    // decrypt C2 URL with Tmlr key
    fcn.00401030(encrypted_C2);
    wsprintfA(buffer, "%s", decrypted_C2);
    CreateThread(NULL, 0, fcn.004024e0, buffer, 0, NULL);
    Sleep(0xcdfe600); // ~216 000 000 ms (~60 hours)
}
ExitProcess(0);

The long Sleep at the end is a simple anti-triage / anti-emulation gate — the process stays alive but idle after spawning the spam thread. ^[r2:main]

fcn.00401030 — Decryptor

Iterates encrypted string, XORs with Tmlr key bytes cycling, then applies bitwise NOT. Writes result in-place. ^[r2:fcn.00401030]

fcn.004024e0 — Spam Thread Dispatcher

srand(GetTickCount());
strcpy(dest, decrypted_C2_URL);
ExpandEnvironmentStringsW("%temp%", ...);
wsprintfW(temp_path, "%sn.txt", temp_dir);
// download victim list
fcn.00401900(1, temp_path, decrypted_URL);
atoi(response) → thread_count;
for (i = 0; i < 100; i++) {
    for (j = 0; j < 50; j++) {
        CreateThread(NULL, 0, fcn.00402340, temp_path, 0, NULL);
        Sleep(rand() % 50 + 50);
    }
    Sleep(20000);
}
DeleteFileW(temp_path);
ExitProcess(0);

^[r2:fcn.004024e0]

C2 Infrastructure

  • External IP check: http://icanhazip.com/ (cleartext HTTP) ^[strings.txt:18]
  • Primary C2: Runtime-decrypted via Tmlr XOR+NOT cipher; not recoverable statically. The encrypted blob is at 0x4041c0 in .rdata.
  • User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/202.0.4664.110 Safari/537.36 ^[strings.txt:17]
  • DNS check: yahoo.com MX resolution via DnsQuery_A before C2 fetch — basic connectivity gating ^[r2:fcn.00401790]
  • SMTP server: Parsed from the downloaded victim list (format user:pass@server:port or similar) ^[r2:fcn.00402340]

Interesting Tidbits

  • Window title: YOU PERVERT! I RECORDED YOU! — a new string not observed in the t2/t4/t5 siblings. Likely used as a MessageBox or window caption if the binary is executed interactively. ^[strings.txt:146]
  • Same BTC wallet as t2/t4/t5: 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K. Campaign-level wallet reuse across at least four confirmed builds spanning ~18 minutes (t2 at 12:15:01, this sample at 12:13:57 — actually this sample predates t2 by ~1 minute, making it the earliest confirmed build in the burst). ^[strings.txt:59]
  • Chrome/202 UA masquerade: Impossible Chrome version 202.0.4664.110 (Chrome stable has never reached v202). Same UA as t4/t5 and edd6ad22 ($800 mutex etyueu). ^[strings.txt:17]
  • No ZIP attachment: Like t2/t4/t5, the email body is plain text — no ZIP constructor. Earlier $1200 variants (150e4652) included a manual ZIP header assembly. This confirms the $800 sub-cluster dropped the ZIP payload. ^[entities/phorpiex.md]
  • MailEnable ESMTP masquerade: Forged Received: header claims MailEnable ESMTP to lend legitimacy. ^[strings.txt:27]
  • Sleep(60h) gate: The main thread sleeps for ~60 hours after spawning the spam thread — a crude but effective anti-sandbox evasion; most sandboxes time out long before the process exits. ^[r2:main]
  • GetTickCount PRNG seeding: Both the downloader and the spam dispatcher seed srand with GetTickCount(), giving thread-sleep jitter that varies per execution. ^[r2:fcn.004024e0]

Deploy / ATT&CK

Technique ID Evidence
User Execution: Malicious File T1204.002 Spam-distributed PE with social-engineered name
Data Encrypted for Impact T1486 Sextortion email demands $800 BTC ransom
Application Layer Protocol: Web Protocols T1071.001 HTTP C2 fetch via WinInet (icanhazip.com, encrypted payload URL)
Application Layer Protocol: Email T1071.003 Self-contained SMTP engine (WS2_32 socket → connect → send/recv)
Exfiltration Over C2 T1041 External IP check + victim-list download over HTTP
Data Manipulation: Transmitted Data T1565.002 Sextortion email body is a fabricated narrative (no actual video)
Masquerading T1036 Fake MailEnable ESMTP Received header; Chrome/202 impossible UA
Anti-Forensics: Data Destruction T1070.004 DeleteFileW on self :Zone.Identifier ADS; temp file deletion after spam loop
Anti-Analysis: Emulation Evasion T1497.001 60-hour Sleep gate; GetTickCount PRNG seeding
Discovery: System Owner/User Discovery T1033 External IP fetch to personalize email headers

Deployable Signatures

YARA

rule phorpiex_sextortion_800_variant {
    meta:
        description = "Phorpiex sextortion spam bot $800 variant (mutex t1/t2/t4/t5)"
        author = "triage-pipeline"
        date = "2026-09-02"
        sha256 = "67ae1ba4090ec9277beb8bdc56379716cc59054d9a5151886cc91838eed217b9"
    strings:
        $mutex_t1 = "t1" ascii wide
        $mutex_t2 = "t2" ascii wide
        $mutex_t4 = "t4" ascii wide
        $mutex_t5 = "t5" ascii wide
        $decrypt_key = "Tmlr" ascii
        $btc_wallet = "1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K" ascii
        $ua = "Chrome/202.0.4664.110 Safari/537.36" ascii
        $extip = "http://icanhazip.com/" ascii
        $mailenable = "MailEnable ESMTP" ascii
        $window_title = "YOU PERVERT! I RECORDED YOU!" ascii wide
        $sextortion_1 = "Unfortunately, there is some bad news for you." ascii
        $sextortion_2 = "I RECORDED YOU (through your camera) MASTURBATING!" ascii
        $sextortion_3 = "All you need is $800 USD in Bitcoin (BTC)" ascii
        $func_1 = { 55 8b ec 83 ec 10 a1 ?? ?? ?? ?? 89 45 f4 } // decryptor prologue
    condition:
        uint16(0) == 0x5a4d and
        filesize < 25KB and
        (
            ($decrypt_key and $btc_wallet) or
            ($ua and $extip and any of ($mutex*)) or
            (2 of ($sextortion*) and $btc_wallet) or
            ($window_title and $mailenable)
        )
}

Behavioral Fingerprint

A PE32 GUI executable under 25 KB, compiled with MSVC 9.0 and linked against MSVCR90.dll, imports WININET.dll, WS2_32.dll, DNSAPI.dll, KERNEL32.dll, and USER32.dll. On launch it creates a named mutex (t1, t2, t4, or t5), deletes its own Zone.Identifier ADS, resolves yahoo.com via DnsQuery_A, fetches an external IP via http://icanhazip.com/, decrypts a C2 URL with the 4-byte key Tmlr (XOR+NOT), downloads a victim list to %TEMP%\<n>.txt, and spawns 50–5000 SMTP worker threads that connect to attacker-provided mail servers and send sextortion emails demanding $800 BTC to 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K. The main thread then sleeps for ~60 hours. Network traffic shows cleartext HTTP to icanhazip.com and SMTP over port 25/587/465 with forged MailEnable ESMTP headers.

IOC List

Type Value
SHA-256 67ae1ba4090ec9277beb8bdc56379716cc59054d9a5151886cc91838eed217b9
SHA-1 4a077a0ed10d4bf84244f50e243608c8a41734bd (.text section)
MD5 787720059300256f7d5e3159ccbe51d7 (.text section)
Mutex t1 (this sample); also t2, t4, t5 in campaign siblings
BTC wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K
Decrypt key Tmlr (XOR+NOT)
User-Agent Mozilla/5.0 ... Chrome/202.0.4664.110 Safari/537.36
External IP URL http://icanhazip.com/
Temp file pattern %TEMP%\<n>.txt
Window title YOU PERVERT! I RECORDED YOU!
SMTP header forgery Received: from ... with MailEnable ESMTP

Detection Signatures

  • capa — signatures not available (capa failed due to missing signature database) ^[capa.txt]. Static detection should rely on YARA + behavioral fingerprint.
  • MITRE ATT&CK — see Deploy/ATT&CK table above.

References

  • phorpiex — cluster entity page
  • /intel/analyses/c3b1b4e4eab9589b9132c57cc6dc9f26b93fee922b78923780cb79ce705f106b.html — sibling t5 ($800 variant)
  • /intel/analyses/dc2936ea921e2cbc56b315d1c08d2c3e1ce4f4e22524c9bdee12a8ea2e037e5a.html — sibling t4 (twin of t5, 44 s earlier)
  • /intel/analyses/5076fdc39445369e67daaccb7ec1699107a5f227aaaec978ec9d77d966124f3d.html — sibling t2 (earliest confirmed build in burst)
  • /intel/analyses/edd6ad227595d25c2cf6cf41d2ac9b6640b2e977aabb2d07eea58fa500b6db19.html — sibling etyueu ($800 variant, earlier campaign)
  • /intel/analyses/150e46523ae4a3e90ce949f15630b2f07d475d3a781188301edded1d527f03af.html — $1200 variant (ZIP constructor present)
  • OpenCTI artifact: b9de1f15-fd21-4b79-8ec1-312e6a0c8d62

Provenance

Static analysis performed on pp-hermes (Linux 6.14.8-2-pve) using radare2 5.9.8. Strings from strings.txt and radare2 /iz. Decompilation via pdc. PE metadata from pefile.txt. File type from file.txt. No dynamic execution — CAPE skipped due to no Windows guest available.